Encrypted Account Commands Keep Secrets Local
For E2EE accounts, the CLI accepts one passphrase only from non-TTY stdin when --e2ee-passphrase-stdin is explicitly present. Never put a passphrase in command arguments, environment variables, config files, logs, examples, or API requests.
Keep your E2EE passphrase in a keystore you choose and manage. That keystore pipes the passphrase directly into the CLI process only when encrypted fields are required. The CLI persists neither value after the process exits.
Decrypt And Encrypt Only In The CLI Process
Pipe Passphrases From Your Own Keystore
# Unsafe
webcull bookmarks get --account <account-hash> --ids 2302 --e2ee-password secret
# macOS Keychain
security find-generic-password -a "$USER" -s webcull-e2ee -w |
webcull bookmarks get --account <account-hash> --ids 2302 --fields id,title,notes --e2ee-passphrase-stdin
# Windows PowerShell with Microsoft.PowerShell.SecretManagement
Get-Secret -Name webcull-e2ee -AsPlainText |
webcull bookmarks get --account <account-hash> --ids 2302 --fields id,title,notes --e2ee-passphrase-stdin
# Linux Secret Service
secret-tool lookup service webcull-e2ee account "$USER" |
webcull bookmarks get --account <account-hash> --ids 2302 --fields id,title,notes --e2ee-passphrase-stdin
Each encrypted operation requires an explicit account and --e2ee-passphrase-stdin. The keystore process writes one passphrase directly to the CLI pipe, so an agent can run the command without receiving or displaying the secret.
The credential names in these examples are placeholders. Configure the entry in your own keystore and use the matching name in the retrieval command. The CLI rejects TTY input, empty input, attached option values, and multiline input.